Your information
Privacy Policy
iDefynMe is designed to help a person reconnect with an advocate without making the purpose of a physical tag obvious. That purpose requires data minimization, careful access controls, and plain explanations of what happens to information.
Effective: October 9, 2026
1. Scope
This policy applies to idefynme.org, the iDefynMe victim experience, and the staff service used by participating organizations. “iDefynMe,” “we,” and “us” refer to the operator of these services.
2. Information we collect
Public website
The public website does not require an account. Hosting and security systems may process ordinary request information such as IP address, browser type, requested page, timestamp, and security signals. We do not use third-party advertising trackers.
Invited staff
We process a staff member’s name, work email address, organization, role, permissions, authentication status, and security events. When staff use Microsoft or Google sign-in, we request only basic identity information: name, email address, and a provider account identifier. We do not request access to Gmail, Google Drive, Google Calendar, contacts, Microsoft mail, OneDrive, or an organization’s directory.
Officer handoffs
We process the fields configured by the participating organization, tag status, case workflow status, assignments, and version history. Officers can access officer-entered information as permitted by the organization but cannot access confidential victim–advocate content.
Victim access and collaboration
A person may claim a preapproved tag using a PIN and passkey. We process a pseudonymous identifier, PIN verifier, passkey public credential and counter, access status, failed-attempt and lockout information, and security events. A device’s fingerprint, face image, or other biometric unlock data remains with the device and is not provided to iDefynMe.
After an advocate releases a workspace, we may process information the person or advocate chooses to provide, including messages, resource activity, appointments, consent choices, notification preferences, and optional contact channels. Contact information is not required to begin.
3. QR codes and browser storage
An iDefynMe QR code contains a high-entropy secret in the URL fragment. A normal browser request does not transmit that fragment to the website. The scanner reads it locally and sends it directly to the same-origin application only when the user proceeds.
Private case content is not stored in browser local storage or an offline service-worker cache. Authentication uses secure, host-only cookies. The service may conceal private content when a browser moves to the background and may require reauthentication after inactivity.
4. How we use information
- Authenticate invited users and enforce organization, role, and field-level permissions.
- Link and manage tags, create secure handoffs, and operate advocate-approved workspaces.
- Deliver requested messages, resources, appointments, and neutral notifications.
- Protect the service, detect abuse, investigate incidents, restore backups, and maintain audit records.
- Comply with applicable law and the participating organization’s approved records and confidentiality obligations.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use Google or Microsoft sign-in data for advertising.
5. When information is disclosed
Information may be disclosed to the participating organization and its authorized personnel according to their roles. Confidential victim–advocate information is separated from officer intake and is not made available to officers.
We use service providers, including Amazon Web Services and the selected identity provider, to host, secure, authenticate, and operate the service. They may process information only for those services and under their applicable agreements. We may also disclose information when required by valid law or when authorized through an applicable, informed release. Victim-service confidentiality rules can restrict disclosure beyond ordinary public-record or legal processes.
6. Retention and deletion
Operational records are retained according to the written schedule approved for the participating organization and applicable law. Security logs, immutable audit records, and encrypted backups can have separate retention periods. Each participating organization must approve and document its applicable schedule and record owner.
When deletion is authorized, information is removed or de-identified from active systems and expires from backups according to the approved backup schedule. Some records may have to be preserved for legal, security, audit, or public-record obligations.
7. Security and safety
We use encryption in transit and at rest, multi-factor authentication for staff, tenant isolation, least-privilege access, database row-level security, protected secrets, versioned changes, monitoring, and redacted audit records. We do not intentionally log QR secrets, PINs, case narratives, private messages, or victim contact details.
No system can guarantee absolute security. Browser history, screenshots, device monitoring, and access by someone who controls a device cannot always be prevented. Users should use the quick-exit control and a safer device when appropriate.
8. Choices and privacy requests
External email, text-message, or browser notifications are opt-in and use neutral wording. A user can change notification preferences in an active workspace or ask the assigned advocate for help.
Depending on applicable law and the organization responsible for a record, a person may request access, correction, deletion, or information about use and disclosure. California law may also provide rights to know, correct, delete, limit certain uses of sensitive information, opt out of sale or sharing, and receive equal service when exercising privacy rights. We do not sell or share information for behavioral advertising.
Send privacy questions or requests to preston@idefynme.org. We may need to verify the request without revealing whether a protected case exists. When a participating organization controls the record, we will route the request to that organization or explain how to contact it.
9. Children and vulnerable users
The service may be used in situations involving minors or vulnerable people only under the participating organization’s approved authority, consent, and confidentiality procedures. iDefynMe does not use their information for advertising or build commercial profiles from it.
10. Changes and contact
We will update the effective date when this policy changes. Material changes affecting active users will be communicated through the service or the participating organization when appropriate.
Questions can be sent to preston@idefynme.org.